Home/Product/lenovo thinkagile mx3331 h firmware
Product

lenovo thinkagile mx3331 h firmware

9 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2023-25492
< 2.93_afbt30p
A valid, authenticated user may be able to trigger a denial of service of the XCC web user interface or other undefined behavior t
6.3MEDIUM
CVE-2023-0683
< 2.93_afbt30p
A valid, authenticated XCC user with read only access may gain elevated privileges through a specifically crafted API call.
8.3HIGH
CVE-2023-29056
< 2.93_afbt30p
A valid LDAP user, under specific conditions, will default to read-only permissions when authenticating into XCC. To be vulnerable
5.3MEDIUM
CVE-2023-25495
< 2.93_afbt30p
A valid, authenticated administrative user can query a web interface API to reveal the configured LDAP client password used by XCC
4.9MEDIUM
CVE-2023-29058
< 2.93_afbt30p
A valid, authenticated XCC user with read-only permissions can modify custom user roles on other user accounts and the user trespa
6.4MEDIUM
CVE-2023-29057
< 2.93_afbt30p
A valid XCC user's local account permissions overrides their active directory permissions under specific configurations. This coul
7.3HIGH
CVE-2022-40134
all versions
An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local
4.4MEDIUM
CVE-2022-34888
< 1.80_afbt20n
The Remote Mount feature can potentially be abused by valid, authenticated users to make connections to internal services that may
2.7LOW
CVE-2022-34884
< 1.80_afbt20n
A buffer overflow exists in the Remote Presence subsystem which can potentially allow valid, authenticated users to cause a recove
7.2HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin